A SOC receives several alerts indicating user accounts are connecting to the company's identity provider through non-secure communications. User credentials for accessing sensitive, business-critical systems could be exposed. Which of the following logs should the SOC use when determining malicious intent?
Intrusion Detection Systems (IDS) logs provide visibility into network traffic patterns and can help detect insecure or unusual connections. These logs will show if non-secure protocols are used, potentially revealing exposed credentials. According to CompTIA CySA+, IDS logs are essential for identifying malicious activity related to communications and network intrusions. Options like DNS (A) and tcpdump (B) provide network details, but IDS specifically monitors for intrusions and unusual activities relevant to security incidents.
Louann
10 months agoAzalee
10 months agoGertude
10 months agoShakira
10 months agoBettina
11 months agoShanice
11 months agoMertie
11 months agoAlecia
11 months agoLovetta
11 months agoAzalee
11 months agoLucia
11 months agoGlen
11 months agoKenda
11 months agoEura
2 years agoSheridan
2 years agoDarell
2 years agoReid
2 years agoMarge
2 years agoRebecka
2 years agoLynna
2 years agoWillard
2 years agoLorrie
2 years agoTerrilyn
2 years agoKris
2 years agoAdell
2 years agoTheron
2 years agoCora
2 years agoTequila
2 years agoTora
2 years agoMeaghan
2 years ago